Risk Management Framework (RMF) Test Engineer

@ General Dynamics Electric Boat
General Dynamics Electric Boatgeneraldynamicselectricboat.com

Risk Management Framework (RMF) Test Engineer

Groton, CT
Posted 3 days ago

About the job

The company maintains cybersecurity and system compliance, supporting Navy accreditation activities. The role involves interpreting RMF requirements, documenting, and improving system security posture in a collaborative environment.

Requirements

  • 2+ years RMF compliance experience
  • 2+ years IT systems exposure
  • Secret security clearance
  • Ability to obtain Top-Secret clearance
  • Experience with security tools

Qualifications

  • High School Diploma or equivalent
  • Experience evaluating RMF compliance
  • Active Security clearance
  • Knowledge of cybersecurity frameworks
  • Organized and detail-oriented

Full job description

Overview

The Pre Commissioning Unit Local Area Network (PCULAN) team is seeking a RMF Cybersecurity Test Engineer to support ongoing system accreditation activities and strengthen the system's overall compliance posture.

The ideal candidate will be able to interpret complex cybersecurity and compliance requirements and translate them into clear, actionable tasks for the team. In this role, they will identify compliance gaps, develop and document mitigation strategies, ensure adherence to applicable policies, and serve as the primary point of contact for Navy system accreditation activities.

Working under the oversight of the ISSO and in conjunction with the Lead System Engineer, the RMF Cybersecurity Test Engineer will help maintain a strong security posture and ensure the system continues to meet all requirements necessary to maintain its accreditation.

This position is 100% on-site with limited expectations for travel.

Duties and Responsibilities include:
  • Interpret and apply RMF requirements across system components
  • Develop, maintain, and update RMF documentation
  • Identify security and compliance gaps on the system
  • Collaborate with the team to improve compliance posture
  • Stay current with STIGs, DoD/Navy guidance, and emerging cybersecurity threats
  • Support vulnerability assessments, remediation efforts, and evidence collection


Qualifications

Required:
  • High School Diploma or equivalent
  • 2+ years of experience evaluating the compliance of a system against the Risk Management Framework (RMF)
  • 2+ years of exposure to IT systems (Active Directory, Exchange, Tanium, Trellix, etc)
  • Current active Secret security clearance is required
  • Ability to obtain and maintain final DoD Top-Secret Clearance.

Preferred:
  • Experience with vulnerability scanning tools (ACAS, Nessus)
  • Experience using system compliance assessment tools (Evaluate STIG, STIG Manager)
  • Experience with compliance reporting (VRAM, CMRS)
  • Working knowledge of Navy Submarine systems and requirements.
  • Current CompTIA Security +


Skills

  • Experience with RMF Authorization To Operate (ATO) packages in Enterprise Mission Assurance Support Service (eMASS)
  • Experience working on cybersecurity RMF body of evidence documentation such as Plan of Action & Milestones.
  • Experience managing multiple projects simultaneously to meet project milestones.
  • Excellent written and verbal communicator.
  • Highly organized, detail-oriented, and capable of managing multiple projects simultaneously.
  • Collaborative professional who works effectively with internal and external entities.


Physical Qualifications

Color Vision, Light Lifting, Pulling, Pushing

Environmental Attributes

Inside
Show full description